DisclosureLens
HackingStolen CredentialsEmployee Data InvolvedDelayed DiscoveryIdentity (basic)Government IDMediumContained

HCI Group

bd_0f6ec265681ba452 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 2, 2020

Filed

Jun 8, 2021

To disclose

40 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for HCI Group2 incidents on file

HCI LLC notified the California Attorney General of a data security incident. On September 2, 2020, HCI became aware that an unauthorized individual had accessed certain employee email accounts sometime prior to June 2020. The breach potentially exposed names and Social Security numbers of current and former employees. HCI engaged forensic investigators and is offering 12 months of identity monitoring services to affected individuals.

California clockDiscovered Sep 2, 2020Notified Jun 8, 2021279d CA 60-day late40 weeks discovery → filing

Incident timeline

undetected · 194 days
discovery → filing · 40 weeks / 279 days

Feb 21, 2020

Begins

Sep 2, 2020

Discovered

Jun 8, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.